Exclusion List
• Manual Checks: Exclude (delete) any unwanted files and folders. Some common file extensions that should usually be excluded are listed below. If the resource you are deleting is a keypath (indicated by the key symbol) you must ensure the related component has been assigned a new keypath. If the component is now empty it can be deleted.
Common Items:HKEY_USER_SELECTABLE\Software\Shortcuts
Event log registries.
All VCache Entries
Shutdown Entries
Uninstall Entries
Your Username if Captured
*.log-app specific
services / hosts – These must be handled appropriately
Folders/ Files referring to Wise
Folders/ Files referring to InstallShield
Any cookies
Any file from the dependency applications that has got captured must be excluded.
Cache
Temp
Tmp
Bag
Log – Examine in notepad to see if they are relevant or not.
• Files*.REG files
_isreg32.dll
setup.exe
install.log
install.exe
install.ini
unwise.exe
Uninstall.xml
Upgrade.exe
Update.exe
uninstall.cif
uninstall.cfg / uninstall.cgf
uninstall.dat
uninstall.dll
uninstall.ini
uninst.exe
uninstall.exe
deinstall.exe
Remove.exe / remove*.exe / *remove.exe
Regsvr16.exe
Regsvr32.exe
services.msc
*.ora files
*.oem files
Hosts File
C:\Temp
Pagefile.sys
C:\Winnt\Recent
Ntuser.ini
Ntuser.dat
Ntuser.dat.log
\Favourites\Desktop.ini
\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.log
\Application Data\Desktop.ini
\Application Data\Microsoft\Internet Explorer\brndlog.txt
\Application Data\Microsoft\Internet Explorer\brndlog.txt.log
\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
\Cookies\index.dat
\NetworkService\LocalSetting\Desktop.ini
Boot.ini
Hiberfil.sys
Ntldr
SchedLgU.txt
C:\RECYCLER
C:\System Volume Information
Local Settings\History\History.IE5
C:\Program Files\Common Files\InstallShield\Engine
C:\Program Files\Common Files\InstallShield\ISCRIPT
C:\Program Files\Common Files\Wise Installation Wizard
C:\Program Files\WindowsUpdate
C:\Program Files\InstallShield Installation Information
C:\Program Files\Sophos SWEEP for NT
C:\Program Files\Uninstall Information
C:\WINDOWS\Debug
C:\WINDOWS\Tasks
C:\WINDOWS\Prefetch
C:\WINDOWS\repair
C:\WINDOWS\CSC
C:\WINDOWS\System32\appmgmt
C:\WINDOWS\System32\CatRoot
C:\WINDOWS\System32\Config
C:\WINDOWS\System32\dllcache
C:\WINDOWS\System32\wbem
Lmscript.pif
Ttfcache
Ffastlog?.*
SMSCFG.ini
Any Cookies
TNSNAMES.ORA If Oracle package, then should be handled carefully. Should be deleted but entries to be appended through CA. Same for SQL.ORA and services file
• Registry:HKEY_CLASSES_ROOT\Interface - all keys under ‘Interface’ can be deleted as they will be recreated automatically
HKEY_LOCAL_MACHINE\CLONE
HKEY_LOCAL_MACHINE\SAM
HKEY_LOCAL_MACHINE\Security
HKEY_LOCAL_MACHINE\Enum
HKEY_LOCAL_MACHINE\Hardware\
HKEY_LOCAL_MACHINE\Software\Novell
HKEY_LOCAL_MACHINE\Software\Program Groups\
HKEY_LOCAL_MACHINE\Software\Classes\
HKEY_LOCAL_MACHINE\Software\Description\Microsoft\Rpc\UuidPersistentData\
HKEY_LOCAL_MACHINE\Software\Description\Microsoft\Rpc\UuidTemporaryData\
HKEY_LOCAL_MACHINE\Software\Description\Microsoft\Rpc\UuidSequenceNumber\
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography
HKEY_LOCAL_MACHINE\Software\Microsoft\Driver Signing
HKEY_LOCAL_MACHINE\Software\Microsoft\DRM
HKEY_LOCAL_MACHINE\Software\Microsoft\EVENTSYSTEM
HKEY_LOCAL_MACHINE\Software\Microsoft\SMS
HKEY_LOCAL_MACHINE\Software\Microsoft\SystemCertificates
HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing
HKEY_LOCAL_MACHINE\Software\Microsoft\Mounted Devices
HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Reliability
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Management
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Controls Folder
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Runonce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run = Synchronization Manager
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SharedDLLs
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Syncmgr
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Autosync
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Windowsupdate
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\GroupPolicy\
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\WinLogon
HKEY_LOCAL_MACHINE\Software\Microsoft\PCHealth\PchSvc
HKEY_LOCAL_MACHINE\Software\Microsoft\Dfrg\BootOptimizeFunction
HKEY_LOCAL_MACHINE\System\Clone
HKEY_LOCAL_MACHINE\System\Mounteddevices
HKEY_LOCAL_MACHINE\System\Select
HKEY_LOCAL_MACHINE\System\Setup
HKEY_LOCAL_MACHINE\System\ControlSet000\
HKEY_LOCAL_MACHINE\System\ControlSet001\
HKEY_LOCAL_MACHINE\System\ControlSet002\
HKEY_LOCAL_MACHINE\System\ControlSet003\
HKEY_LOCAL_MACHINE\System\ControlSet004\
HKEY_LOCAL_MACHINE\System\ControlSet005\
HKEY_LOCAL_MACHINE\System\ControlSet006\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\SessionManager\Environment\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\hardwareProfiles\
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\DHCP
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\ E100b1\Parameters\Tcpip
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Security
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\System
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\IDISW2KM\Enum
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kmixer
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Netlogon
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NMSCFG\Security
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NWCWorkstation
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\TRKWKS
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8AAE3FAA-E935-4AB3-B74C-55E12729E3DA}
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\DHCP
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\VxD\VCACHE
HKEY_CURRENT_USER\SessionInformation
HKEY_CURRENT_USER\Volatile Environment
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\GRPCONV
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Applets
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\SessionInfo
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\StreamMRU
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\MountPoints
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\StartPage
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Prefetcher
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\IME\China\IMEPY\TIPMIG
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Syncmgr\Handlers
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Shellbrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Explorer
HKEY_CURRENT_USER\Software\Microsoft\Windows\Shell
HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates
HKEY_CURRENT_USER\Control Panel\Desktop
HKEY_CURRENT_USER\Control Panel\Keyboard\InitialKeyboardIndicators
HKEY_USERS\Software\Microsoft\SystemCertificates